CVE-2018-21270

CWE-125Out-of-bounds Read7 documents6 sources
Severity
6.5MEDIUM
EPSS
0.5%
top 32.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 3

Description

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:HExploitability: 2.2 | Impact: 4.2

Affected Packages3 packages

Debiannode-stringstream< 0.0.6-1+3
npmstringstream< 0.0.6
NVDnodejs/node.js< 0.0.6

🔴Vulnerability Details

4
CVEList
CVE-2018-21270: Versions less than 02020-12-03
OSV
CVE-2018-21270: Versions less than 02020-12-03
GHSA
Out-of-bounds Read in stringstream2019-06-20
OSV
Out-of-bounds Read in stringstream2019-06-20

📋Vendor Advisories

2
Red Hat
nodejs-stringstream: out-of-bounds read leading to uninitialized memory exposure2020-05-16
Debian
CVE-2018-21270: node-stringstream - Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an...2018
CVE-2018-21270 (MEDIUM CVSS 6.5) | Versions less than 0.0.6 of the Nod | cvebase.io